9.8 CRITICAL
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
Sandbox escape due to incorrect boundary conditions in the Graphics component
Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability affects Firefox < 147, Firefox ESR < 115.32, and Firefox ESR < 140.7.
References
Affected products
- <147
- <140.7
- <115.32
- <140.7
- <147
Matching in nixpkgs
pkgs.xulrunner
Web browser built from Firefox source tree
pkgs.firefoxpwa
Tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox (native component)
pkgs.faust2firefox
The faust2firefox script, part of faust functional programming language for realtime audio signal processing
pkgs.firefox_decrypt
Tool to extract passwords from profiles of Mozilla Firefox and derivates
pkgs.pkgsRocm.firefox
Web browser built from Firefox source tree
pkgs.firefox-unwrapped
Web browser built from Firefox source tree
pkgs.firefox-gnome-theme
GNOME theme for Firefox
pkgs.firefox-sync-client
Commandline-utility to list/view/edit/delete entries in a firefox-sync account
pkgs.pkgsRocm.firefoxpwa
Tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox (native component)
pkgs.firefox-esr-unwrapped
Web browser built from Firefox source tree
-
nixos-unstable 140.1.0esr
- nixpkgs-unstable 140.1.0esr
- nixos-unstable-small 140.1.0esr
-
nixos-25.11 140.6.0esr
- nixpkgs-25.11-darwin 140.6.0esr
pkgs.pkgsRocm.firefox-beta
Web browser built from Firefox Beta Release source tree
pkgs.thunderbird-unwrapped
Full-featured e-mail client
-
nixos-25.11 146.0.1
pkgs.firefox-beta-unwrapped
Web browser built from Firefox Beta Release source tree
pkgs.pkgsRocm.firefox-mobile
Web browser built from Firefox source tree
pkgs.firefox-esr-128-unwrapped
Web browser built from Firefox source tree
-
nixos-unstable 128.13.0esr
- nixpkgs-unstable 128.13.0esr
- nixos-unstable-small 128.13.0esr
pkgs.thunderbird-128-unwrapped
Full-featured e-mail client
-
nixos-unstable 128.13.0esr
- nixpkgs-unstable 128.13.0esr
- nixos-unstable-small 128.13.0esr
pkgs.thunderbird-140-unwrapped
Full-featured e-mail client
-
nixos-25.11 140.6.0esr
pkgs.thunderbird-esr-unwrapped
Full-featured e-mail client
-
nixos-unstable 128.13.0esr
- nixpkgs-unstable 128.13.0esr
- nixos-unstable-small 128.13.0esr
-
nixos-25.11 140.6.0esr
pkgs.pkgsRocm.firefox-unwrapped
Web browser built from Firefox source tree
pkgs.pkgsRocm.firefox-devedition
Web browser built from Firefox Developer Edition source tree
pkgs.pkgsRocm.thunderbird-latest
Full-featured e-mail client
pkgs.firefox-devedition-unwrapped
Web browser built from Firefox Developer Edition source tree
pkgs.thunderbird-latest-unwrapped
Full-featured e-mail client
-
nixos-25.11 146.0.1
pkgs.pkgsRocm.firefox-beta-unwrapped
Web browser built from Firefox Beta Release source tree
pkgs.thunderbirdPackages.thunderbird
Full-featured e-mail client
-
nixos-25.11 146.0.1
pkgs.gnomeExtensions.firefox-profiles
Easily launch Firefox with your favorite profile right from the indicator menu!
pkgs.roundcubePlugins.thunderbird_labels
None
pkgs.thunderbirdPackages.thunderbird-128
Full-featured e-mail client
-
nixos-unstable 128.13.0esr
- nixpkgs-unstable 128.13.0esr
- nixos-unstable-small 128.13.0esr
pkgs.thunderbirdPackages.thunderbird-140
Full-featured e-mail client
-
nixos-25.11 140.6.0esr
pkgs.thunderbirdPackages.thunderbird-esr
Full-featured e-mail client
-
nixos-unstable 128.13.0esr
- nixpkgs-unstable 128.13.0esr
- nixos-unstable-small 128.13.0esr
-
nixos-25.11 140.6.0esr
- nixpkgs-25.11-darwin 140.6.0esr
pkgs.pkgsRocm.firefox-devedition-unwrapped
Web browser built from Firefox Developer Edition source tree
pkgs.thunderbirdPackages.thunderbird-latest
Full-featured e-mail client
pkgs.pkgsRocm.thunderbirdPackages.thunderbird-latest
Full-featured e-mail client
Package maintainers
-
@pmahoney Patrick Mahoney <pat@polycrystal.org>
-
@magnetophon Bart Brouns <bart@magnetophon.nl>
-
@jopejoe1 jopejoe1 <nixpkgs@missing.ninja>
-
@rhendric Ryan Hendrickson
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>
-
@ambroisie Bruno BELANYI <bruno.nixpkgs@belanyi.fr>
-
@schnusch schnusch
-
@unode Renato Alves <alves.rjc@gmail.com>
-
@pasqui23 pasqui23 <p3dimaria@hotmail.it>
-
@camillemndn Camille M. <camillemondon@free.fr>
-
@honnip Jung seungwoo <me@honnip.page>
-
@nbp Nicolas B. Pierron <nixos@nbp.name>
-
@lovesegfault Bernardo Meurer <meurerbernardo@gmail.com>
-
@vcunat Vladimír Čunát <v@cunat.cz>
-
@felschr Felix Schröter <dev@felschr.com>
-
@nekowinston winston <hey@winston.sh>
-
@booxter Ihar Hrachyshka <ihar.hrachyshka@gmail.com>